{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,10,22]],"date-time":"2024-10-22T23:15:03Z","timestamp":1729638903984,"version":"3.28.0"},"reference-count":32,"publisher":"IEEE","license":[{"start":{"date-parts":[[2021,7,18]],"date-time":"2021-07-18T00:00:00Z","timestamp":1626566400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,7,18]],"date-time":"2021-07-18T00:00:00Z","timestamp":1626566400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,7,18]],"date-time":"2021-07-18T00:00:00Z","timestamp":1626566400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,7,18]]},"DOI":"10.1109\/ijcnn52387.2021.9533777","type":"proceedings-article","created":{"date-parts":[[2021,9,20]],"date-time":"2021-09-20T21:27:41Z","timestamp":1632173261000},"page":"1-8","source":"Crossref","is-referenced-by-count":2,"title":["Constraining Logits by Bounded Function for Adversarial Robustness"],"prefix":"10.1109","author":[{"given":"Sekitoshi","family":"Kanai","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Masanori","family":"Yamada","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shin'ya","family":"Yamaguchi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hiroshi","family":"Takahashi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yasutoshi","family":"Ida","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref32","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume":"97","author":"zhang","year":"2019","journal-title":"Proc ICML"},{"journal-title":"Wide residual networks","year":"2016","author":"zagoruyko","key":"ref31"},{"key":"ref30","doi-asserted-by":"crossref","DOI":"10.7551\/mitpress\/10761.003.0012","article-title":"11 adversarial perturbations of deep neural networks","volume":"311","author":"warde-farley","year":"2016","journal-title":"Perturbation Optimization and Statistics"},{"journal-title":"Evaluating and Understanding the Robustness of Adversarial Logit Pairing","year":"2018","author":"engstrom","key":"ref10"},{"key":"ref11","article-title":"Generalizable adversarial training via spectral normalization","author":"farnia","year":"2019","journal-title":"Proc ICLR"},{"journal-title":"Regularisation of neural networks by enforcing lipschitz continuity","year":"2018","author":"gouk","key":"ref12"},{"journal-title":"Uncovering the limits of adversarial training against norm-bounded adversarial examples","year":"2020","author":"gowal","key":"ref13"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"journal-title":"Adversarial logit pairing","year":"2018","author":"kannan","key":"ref15"},{"key":"ref16","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009","journal-title":"Tech Rep"},{"journal-title":"Adversarial machine learning at scale","year":"2016","author":"kurakin","key":"ref17"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref19","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"Proc ICLR"},{"key":"ref28","first-page":"6542","article-title":"Lipschitz-margin training: Scalable certification of perturbation invariance for deep neural networks","author":"tsuzuku","year":"2018","journal-title":"Proc NeurIPS"},{"key":"ref4","first-page":"11190","article-title":"Unlabeled data improves adversarial robustness","author":"carmon","year":"2019","journal-title":"Proc NeurIPS"},{"journal-title":"Intriguing properties of neural networks","year":"2013","author":"szegedy","key":"ref27"},{"journal-title":"On evaluating adversarial robustness","year":"2019","author":"carlini","key":"ref3"},{"key":"ref6","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","author":"croce","year":"2020","journal-title":"Proc ICML"},{"key":"ref29","first-page":"5025","article-title":"Adversarial risk and the dangers of evaluating against weak attacks","volume":"80","author":"uesato","year":"2018","journal-title":"Proc ICML"},{"key":"ref5","first-page":"854","article-title":"Parseval networks: Improving robustness to adversarial examples","author":"cisse","year":"2017","journal-title":"Proc ICML"},{"key":"ref8","first-page":"1675","article-title":"Gradient descent finds global minima of deep neural networks","author":"du","year":"2019","journal-title":"Proc ICML"},{"journal-title":"AdverTorch v0 1 An adversarial robustness toolbox based on pytorch","year":"2019","author":"ding","key":"ref7"},{"key":"ref2","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"Proc ICML"},{"journal-title":"Gradient descent provably optimizes over-parameterized neural networks","year":"2018","author":"du","key":"ref9"},{"key":"ref1","article-title":"Square attack: a query-efficient black-box adversarial attack via random search","author":"andriushchenko","year":"2020","journal-title":"Proc ECCV"},{"journal-title":"Logit pairing methods can fool gradient-based attacks","year":"2018","author":"mosbach","key":"ref20"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/K18-2019"},{"key":"ref21","article-title":"Rethinking softmax cross-entropy loss for adversarial robustness","author":"pang","year":"2020","journal-title":"Proc ICLR"},{"key":"ref24","article-title":"Batch-wise logit-similarity: Generalizing logit-squeezing and label-smoothing","author":"shafahi","year":"2019","journal-title":"Proc BMVC"},{"journal-title":"Label smoothing and Logit squeezing A replacement for adversarial training?","year":"2019","author":"shafahi","key":"ref23"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"journal-title":"Improved adversarial robustness via logit regularization methods","year":"2019","author":"summers","key":"ref25"}],"event":{"name":"2021 International Joint Conference on Neural Networks (IJCNN)","start":{"date-parts":[[2021,7,18]]},"location":"Shenzhen, China","end":{"date-parts":[[2021,7,22]]}},"container-title":["2021 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9533266\/9533267\/09533777.pdf?arnumber=9533777","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,9]],"date-time":"2023-11-09T02:50:52Z","timestamp":1699498252000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9533777\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,18]]},"references-count":32,"URL":"https:\/\/doi.org\/10.1109\/ijcnn52387.2021.9533777","relation":{},"subject":[],"published":{"date-parts":[[2021,7,18]]}}}